8e6 Technologies ER HL/SL manual Use Enterprise Reporter to conduct an investigation

Page 13

CONFIGURE, TEST THE ENTERPRISE REPORTER USE ENTERPRISE REPORTER TO CONDUCT AN INVESTIGATION

Use Enterprise Reporter to conduct an investigation

Once custom category groups and user groups have been created, administrators can begin running their first reports. In most cases, administrators will employ the Enterprise Reporter as a forensic tool to determine if anomalous Internet behavior exists in their organization. In order to facilitate this process, the Enterprise Reporter menu structure is organized to follow the normal process flow of an inves- tigation.

1.First, the administrator is greeted with a dashboard of high-level reports called “Canned Reports.” By viewing these canned reports, an administrator can quickly determine if there is any anomalous behavior that needs investigation.

For example, a high level of spyware site activity might be found under a specific username, or a high rate of traffic identified in the “PornographyAdult Content” category. If something is detected that warrants further investigation, one would then proceed to the “Drill Down Report” section.

2.The next stage of the investigation is to select the Drill Down Report menu. The Drill Down Report is a multi-dimensional database that allows the user to drill down to the source of any Internet threat.

For example, if there is unusually high page count in the “Pornography/Adult Content” category, the administrator can drill down into the Category/User section to determine who is viewing this material. Once a specific end user is identified, the administrator can then delve into the detail page view section to see the exact pages that end user has been visiting.

This detailed information provides a wealth of information on the exact time the page was visited, the user’s IP address, whether the site was blocked by the R3000 filter, how it was blocked (e.g. in URL library, blocked keyword, proxy pattern blocking, etc), and the full-length URL. By viewing this detail, the admin- istrator can obtain an accurate gauge of the user’s intent—whether the user repeatedly attempted to go to a forbidden site or whether it was an isolated inci- dent.

3.The last stage of an investigation is to document the long-term activity of a policy violator, since most organizations require more than one or two events to reprimand a user. Once the administrator determines the name of the user and the Web sites visited in the Drill Down Report, the next step is to run a custom report. The administrator can run a specific search of the policy violator for a custom time period by selecting the Custom Report Wizard option in the Custom Reports menu. When generating this report, a custom time scope, specific category, and name of a specific end user can be specified.

As an example, the administrator would probably run a custom report for the policy violator by specifying the category “Pornography/Adult Content” and all activity within that category within the last month. The administrator can then save a PDF version of the report for documentation purposes. This custom report provides the necessary forensic information to support any internal repri- mand and to protect the organization in the event the incident goes to court.

To summarize, the aforementioned steps were provided to give the user a most- likely use case for the 8e6 Enterprise Reporter. The next section provides a more in-depth view of how to navigate within each of the main sections of the Enterprise Reporter: Canned Reports, Drill Down Reports, and Custom Reports.

8E6 TECHNOLOGIES, ENTERPRISE REPORTER EVALUATION GUIDE

9

Image 13
Contents Guide Enterprise Reporter Evaluation Guide Contents Create a Custom Report for a specific user Overview Install the Enterprise Reporter Understand the most common and useful features How to add a Category Group How to create custom Category GroupsUse custom Category Groups to narrow your search Group Information frameGroup Definitions frame How to add Categories to a Category Group Use custom User Groups to narrow your search How to create User Groups Add a User Group Define a User Group Rebuild Groups Use Enterprise Reporter to conduct an investigation Use Enterprise Reporter Canned Reports How to generate a Canned Report 8E6 TECHNOLOGIES, Enterprise Reporter Evaluation Guide Use Enterprise Reporter Drill Down Reports How to export a Canned ReportHow to generate a Summary Drill Down Report Report columns Summary Drill Down Report navigationFilter columns and buttons Count columns Sort records by another column Navigation tipsBack button Record navigation fieldReport type columns Detail Drill Down Report navigationLinks Select a specific user by Category Evaluation stepsSort by Filter Action column Full URL reviewSort by Search String Sort by Content TypeCreate a Custom Report for a specific user How to use the Custom Report WizardGenerate a new Custom Report Custom Report Wizard Specific User Detail by Page report Export a Custom Report Save a Detail Custom Report 8E6 TECHNOLOGIES, Enterprise Reporter Evaluation Guide Enter a Name for the event Schedule a report to run8E6 TECHNOLOGIES, Enterprise Reporter Evaluation Guide Appendix a Samples of Commonly Used Reports How to generate a Sample Custom ReportReport format Examples of available Sample Custom ReportsSample Report 1 Top 20 Users by Category/User Sample User/Sites report Sample Report 2 Top 20 Sites by User/SiteSample Category/User/Sites report Sample Report 3 By Category/User/SiteRecord exportation tip Appendix B Export and Save Summary ReportsSelect records to be exported Use header buttons for report customizationExport a Summary Drill Down Report How to save a Summary Drill Down Report 8E6 TECHNOLOGIES, Enterprise Reporter Evaluation Guide Set Result Limit Other Summary Report toolsReport fields Type fieldDisplay and # Records fields Sort by and Order fields Search and Filter String fieldsBreak type field Format fieldFor double-break reports only For pie and bar charts onlyEmail option Methods for exporting a Drill Down ReportView and print options View and print tools Sample report file formats8E6 TECHNOLOGIES, Enterprise Reporter Evaluation Guide